🏈 What the Cleveland Browns and Your CISO Have in Common

Since the Cleveland Browns returned in 1999, they’ve had 12 head coaches and one of the worst records in the league. The same instability plagues many organizations’ cybersecurity programs — where the average CISO lasts just 18–26 months. This article draws a clear parallel between leadership turnover in football and the boardroom, showing how frequent change weakens strategy, culture, and overall defense.

Spoiler: It’s a revolving door problem — and it’s costing both teams and companies the win.


The Cleveland Coach Carousel 🎠

Since the Browns returned to Cleveland in 1999, fans have endured what feels like a never-ending parade of head coaches.

In just over two decades, the Browns have cycled through 12 full-time head coaches — not including interim stand-ins. That’s an average tenure of roughly two years per coach.

The result?
A record of 142–283–1 — a .335 win percentage that tells a clear story: constant leadership turnover kills momentum.

Each new coach brings a new system, new staff, new philosophy. Players must relearn playbooks. Culture resets. And just when things start to click — a new face walks through the door with another “five-year plan.”

It’s not just instability — it’s instability institutionalized.

(And no, we’re not even going to talk about quarterbacks… we all know that list is longer than a CVS receipt.)


The CISO: The Head Coach of Your Cyber Defense

Now let’s switch from the 50-yard line to the boardroom.

The Chief Information Security Officer (CISO) is your organization’s defensive coach — responsible for strategy, alignment, and execution across a complex playbook of risks.

But just like the Browns’ sideline, CISO turnover is notoriously high.

  • The average CISO tenure is around 18 to 26 months, far shorter than other C-suite roles.

  • In comparison, CIOs average 4–5 years, and CEOs even longer.

  • Some Fortune 500 companies do better (around 4.5 years, according to Fortify Experts), but many mid-market firms churn CISOs faster than they can update their LinkedIn bios.

Why? Burnout, unclear authority, unrealistic expectations, and a disconnect between boards and technical teams. Sound familiar?


When Leadership Turns Over, So Does the Playbook

The parallels are almost painful:

ThemeCleveland BrownsCorporate Cybersecurity
Leadership Instability12 coaches in 25 yearsCISO average tenure ≈ 2 years
Constant ChangeNew systems, staff, and culture resetsNew vendors, frameworks, and shifting priorities
Lack of ContinuityPlayers relearn every seasonTeams reorg after every leadership change
Performance ImpactLosing seasons pile upSecurity posture weakens, risk visibility fades
Root CauseOwnership dysfunction, short-term thinkingBoard misalignment, unclear expectations

The Browns’ record is on display for the world to see — the win/loss column doesn’t lie.

But your company’s cybersecurity record isn’t nearly as visible. You don’t get a Monday-morning box score for “attacks prevented” or “risks mitigated.”

Still, make no mistake: the higher the CISO turnover, the worse your overall security posture likely is.


The Takeaway for Boards 🧠

If you’re sitting on a board, here’s a question worth asking:

“How many CISOs have we had in the past five years?”

If the answer makes you wince, there’s a deeper problem — not just with the CISO, but with how the organization supports (or undermines) that role.

Strong defenses come from stability, trust, and long-term strategy, not quick fixes or new hires every two years.

So the next time you’re tempted to swap out your CISO hoping for a “fresh start,” remember:

You can’t win championships by constantly changing coaches.
(And seriously — let’s not start counting quarterbacks, okay?)


⚖️ Possible Objections & Caveats

  • Not every turnover is bad — sometimes a change is needed due to mismatch, unethical behavior, or stalled performance.

  • Some organizations may require a “turnaround CISO”, just as some franchises hire a firebrand coach to rebuild culture and discipline.

  • Fortune-level CISOs may enjoy longer tenure; averages often mask the variance between SMBs and enterprise-scale environments. (Source: Fortify Experts)

  • Winning in football is zero-sum and binary (win vs. lose); cyber defense is probabilistic — many interventions only show their value over time, not in a single “season.”

 

RELATED POSTS

Discover more from Stasiak

Subscribe now to keep reading and get access to the full archive.

Continue reading

[mailpoet_form id="5"]
[mailpoet_form id="1"]